hizel писал(а):*недоумение*
только tcpdump видимо прольет свет понимания на эту ситуацию
Попробовал tcpdump правда мало что понял вот логи в двух случаях
1. Нат на em0 и соответсвенно сервер по ip em0 только пингуется
Код: Выделить всё
20:16:19.938680 IP 10.27.0.1.ndm-requester > 10.27.0.20.ssh: S 500718261:500718261(0) win 65535 <mss 1460,nop,nop,sackOK>
20:16:19.938710 IP 10.27.0.20.ssh > 10.27.0.1.ndm-requester: S 2829909988:2829909988(0) ack 500718262 win 65535 <mss 1460,sackOK,eol>
20:16:20.254464 IP 10.27.0.20.33960 > 10.27.0.254.domain: 43846+ PTR? 20.0.27.10.in-addr.arpa. (41)
20:16:22.825021 IP 10.27.0.1.ndm-requester > 10.27.0.20.ssh: S 500718261:500718261(0) win 65535 <mss 1460,nop,nop,sackOK>
20:16:22.825031 IP 10.27.0.20.ssh > 10.27.0.1.ndm-requester: S 2829909988:2829909988(0) ack 500718262 win 65535 <mss 1460,sackOK,eol>
20:16:25.357527 IP 10.27.0.20.33960 > 10.27.0.254.domain: 43846+ PTR? 20.0.27.10.in-addr.arpa. (41)
20:16:25.886113 IP 10.27.0.20.ssh > 10.27.0.1.ndm-requester: S 2829909988:2829909988(0) ack 500718262 win 65535 <mss 1460,sackOK,eol>
20:16:28.840694 IP 10.27.0.1.ndm-requester > 10.27.0.20.ssh: S 500718261:500718261(0) win 65535 <mss 1460,nop,nop,sackOK>
20:16:28.840704 IP 10.27.0.20.ssh > 10.27.0.1.ndm-requester: S 2829909988:2829909988(0) ack 500718262 win 65535 <mss 1460,sackOK,eol>
20:16:31.901596 IP 10.27.0.20.ssh > 10.27.0.1.ndm-requester: S 2829909988:2829909988(0) ack 500718262 win 65535 <mss 1460,sackOK,eol>
20:16:35.562982 IP 10.27.0.20.27222 > 10.27.0.254.domain: 43847+ PTR? 1.0.27.10.in-addr.arpa. (40)
20:16:38.024229 IP 10.27.0.20.ssh > 10.27.0.1.ndm-requester: S 2829909988:2829909988(0) ack 500718262 win 65535 <mss 1460,sackOK,eol>
20:16:40.666148 IP 10.27.0.20.27222 > 10.27.0.254.domain: 43847+ PTR? 1.0.27.10.in-addr.arpa. (40)
20:16:50.269494 IP 10.27.0.20.ssh > 10.27.0.1.ndm-requester: S 2829909988:2829909988(0) ack 500718262 win 65535 <mss 1460,sackOK,eol>
20:16:51.892036 IP 10.27.0.20.49598 > 10.27.0.254.domain: 43848+ PTR? 254.0.27.10.in-addr.arpa. (42)
20:16:56.995210 IP 10.27.0.20.49598 > 10.27.0.254.domain: 43848+ PTR? 254.0.27.10.in-addr.arpa. (42)
20:17:30.913703 IP 10.27.0.1 > 10.27.0.20: ICMP echo request, id 1024, seq 19968, length 40
20:17:30.913714 IP 10.27.0.20 > 10.27.0.1: ICMP echo reply, id 1024, seq 19968, length 40
20:17:31.905883 IP 10.27.0.1 > 10.27.0.20: ICMP echo request, id 1024, seq 20224, length 40
20:17:31.905891 IP 10.27.0.20 > 10.27.0.1: ICMP echo reply, id 1024, seq 20224, length 40
20:17:58.501248 IP 10.27.0.1.netbios-dgm > 10.27.0.255.netbios-dgm: NBT UDP PACKET(138)
2. Тут нат отключен и к серверу подключает.
Код: Выделить всё
20:22:21.965945 arp who-has 10.27.0.20 tell 10.27.0.1
20:22:21.965959 arp reply 10.27.0.20 is-at 00:1b:21:22:e3:dd (oui Unknown)
20:22:21.966566 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: S 2987811056:2987811056(0) win 65535 <mss 1460,nop,nop,sackOK>
20:22:21.966592 IP 10.27.0.20.ssh > 10.27.0.1.timbuktu-srv2: S 2301099375:2301099375(0) ack 2987811057 win 65535 <mss 1460,sackOK,eol>
20:22:21.966940 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: . ack 1 win 65535
20:22:22.016512 IP 10.27.0.20.ssh > 10.27.0.1.timbuktu-srv2: P 1:40(39) ack 1 win 65535
20:22:22.017037 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: P 1:29(28) ack 40 win 65496
20:22:22.017162 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: P 29:541(512) ack 40 win 65496
20:22:22.017169 IP 10.27.0.20.ssh > 10.27.0.1.timbuktu-srv2: . ack 541 win 65188
20:22:22.017172 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: P 541:645(104) ack 40 win 65496
20:22:22.018000 IP 10.27.0.20.ssh > 10.27.0.1.timbuktu-srv2: P 40:776(736) ack 645 win 65084
20:22:22.018536 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: P 645:661(16) ack 776 win 64760
20:22:22.023327 IP 10.27.0.20.ssh > 10.27.0.1.timbuktu-srv2: P 776:1312(536) ack 661 win 65535
20:22:22.209684 IP 10.27.0.20.42304 > 10.27.0.254.domain: 31433+ PTR? 20.0.27.10.in-addr.arpa. (41)
20:22:22.210801 IP 10.27.0.254.domain > 10.27.0.20.42304: 31433 NXDomain 0/1/0 (91)
20:22:22.210881 IP 10.27.0.20.25188 > 10.27.0.254.domain: 31434+ PTR? 1.0.27.10.in-addr.arpa. (40)
20:22:22.211800 IP 10.27.0.254.domain > 10.27.0.20.25188: 31434 NXDomain 0/1/0 (90)
20:22:22.235286 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: . ack 1312 win 64224
20:22:22.250153 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: P 661:1173(512) ack 1312 win 64224
20:22:22.250158 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: P 1173:1189(16) ack 1312 win 64224
20:22:22.250165 IP 10.27.0.20.ssh > 10.27.0.1.timbuktu-srv2: . ack 1189 win 65172
20:22:22.266497 IP 10.27.0.20.ssh > 10.27.0.1.timbuktu-srv2: P 1312:2352(1040) ack 1189 win 65535
20:22:22.454036 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: . ack 2352 win 65535
20:22:22.566722 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: P 1189:1205(16) ack 2352 win 65535
20:22:22.567221 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: P 1205:1257(52) ack 2352 win 65535
20:22:22.567228 IP 10.27.0.20.ssh > 10.27.0.1.timbuktu-srv2: . ack 1257 win 65535
20:22:22.567278 IP 10.27.0.20.ssh > 10.27.0.1.timbuktu-srv2: P 2352:2404(52) ack 1257 win 65535
20:22:22.782098 IP 10.27.0.1.timbuktu-srv2 > 10.27.0.20.ssh: . ack 2404 win 65483
20:22:23.232123 IP 10.27.0.20.62403 > 10.27.0.254.domain: 31435+ PTR? 254.0.27.10.in-addr.arpa. (42)
20:22:23.233214 IP 10.27.0.254.domain > 10.27.0.20.62403: 31435 NXDomain 0/1/0 (92)